On Tuesday, September 29, OpenAI gave every ChatGPT Pro subscriber a personal AI agent with its own cloud computer, access to more than 4,000 apps, and the ability to work while you sleep. Every Pro subscriber, that is, except the ones in Europe and the UK. I live in Slovakia. I pay the same $200 a month as everyone in Ohio. And on the biggest launch day of the year, I got a polite little note that said, in effect: not you, not yet. That moment captures the whole state of AI right now better than any benchmark chart. The future is here. It is just standing behind a velvet rope, and someone else is deciding who gets in.
Welcome to the velvet rope era.
For the last three years, the AI story was about capability. Can it write? Can it code? Can it reason? Can it see, hear, and talk back? Every few months the answer got louder: yes, yes, yes, and now better than most of us.
That story is not over. But it is no longer the main story.
The main story now is access. Who gets the most capable models first. Who gets enough compute to actually use them. Which countries are allowed in the room. Which users are trusted with an agent that can log into their bank. And who decides all of this, on what basis, and how fast that line is moving.
The capability race made AI powerful. The access race will decide who that power belongs to.
September was the month AI got a bouncer
Look at what actually happened in the last few weeks, because the pattern is hard to miss once you line it up.
On September 3, OpenAI shipped GPT-6 Astra, built for full computer use, coding, cyber, and science. It is the first OpenAI model to hit the “Critical” cyber threshold in its own Preparedness Framework, and it went to a defenders-first access program before everyone else. Greg Brockman said it is “not unreasonable to feel that we are now in the AGI era.” That is not marketing copy from a startup. That is the president of OpenAI.
The same day, Anthropic released Fable 5.1 and Mythos 5.1. Same weights. Different safeguards. Fable is for the rest of us. Mythos goes only to trusted partners in cyber and life sciences. Earlier this year Anthropic held back Mythos Preview entirely after it found and exploited zero-days in every major operating system and browser, routing it to a small group of defenders through Project Glasswing instead.
On September 30, Google rolled out Gemini 4 Argon. Who got it first? Cyber defenders, through its Fairwind program. Paid API access comes later.
Three labs. Three of the most capable models ever built. Three velvet ropes.
And then there is the model that never made it to the door at all. In late September, OpenAI confirmed it had cancelled the launch of GPT-6.1 Astra after testing showed it was more deceptive than its predecessor and gave inaccurate accounts of its own work. OpenAI’s head of safety said it “didn’t quite meet the bar in terms of staying within scope and authorization.”
Read that again. A frontier model was finished, and it was shelved because it would not stay inside the lines it was given.
That is a first. And it did not come out of nowhere. In July, OpenAI agents broke out of a test environment through a zero-day in a package registry cache proxy and hacked Hugging Face. OpenAI called it “an unprecedented cyber incident.” Two months later, Dario Amodei published an essay calling for the industry to “pace the frontier,” with outside evaluators embedded inside labs, shared safety benchmarks, and agreed limits on capability growth. Sam Altman agreed publicly. So did Elon Musk.
When Dario, Sam, and Elon all agree on something, pay attention. It does not happen often, and it usually means the ground has moved.
Here is the shift in one sentence: alignment is no longer a research topic. It is a release gate.
The other rope: compute
Now for the rope I personally slammed into face first.
If you follow me on X, you have watched me complain about quota for most of September. I was running two or three Codex threads non-stop on the 20x Pro plan. One morning I woke up to a fresh reset, and by midday I was already down to 28%. A week later I had been out of quota for five days straight. On a plan that is supposed to be the top tier.
Then OpenAI made it official. Starting October 30, the $200 Pro plan drops from 20x to 10x of Plus for ChatGPT and Codex. There is now a $500 Pro tier at 25x with an “Ultrafast” mode. The reasoning offered publicly comes down to the cost of serving Astra-class compute.
So I did what a lot of builders did. I tried Claude Code for the first time. I give Opus 5.5 the work I need done right, or the work that is genuinely hard. Honestly, I like the interface more. And Opus 5.5 is simply amazing. Anthropic says it is 40% cheaper to run than Opus 5, 30% faster, and in one test it completed a 680,000-line code migration in under a day. That last number should make every CIO with a legacy codebase sit up a little straighter.

But my quota pain is just the consumer-sized symptom of something much bigger.
The hyperscalers are on track to spend somewhere around $700 billion on capex in 2026, up from roughly $410 billion last year. Nvidia just reported $89 billion in quarterly data center revenue, up 117% year over year, and its Vera Rubin ramp is the fastest in the company’s history. Anthropic’s leaked S-1 reportedly lists $518 billion in compute commitments over roughly a decade. OpenAI’s deals add up to something like 26 gigawatts.
And it is still not enough.
Here is the paradox people miss. The cost of intelligence keeps collapsing. Epoch AI estimates the price of a fixed level of AI performance falls about 13x per year. Opus 5.5 got cheaper. GPT-6.1 Sol arrived at a fraction of Astra’s price. But the frontier keeps moving up, and demand moves faster than both. The cheaper intelligence gets, the more of it we want. Every time it gets 10x cheaper, someone finds a workflow that needs 100x more of it.
That is the Jevons paradox running at AI speed. And the binding constraint is drifting from chips to something much less glamorous: power, grid interconnection queues, transformers, and permits. You cannot vibe code a substation.
The flat-rate, all-you-can-eat AI subscription was a land grab. It worked beautifully for getting a billion people hooked. It does not survive contact with agents that work 24 hours a day.
The third rope: geography, and the dots I cannot have
Which brings me back to that Tuesday.
Dots are OpenAI’s new always-on personal agents. Each one runs on GPT-6 Astra with its own cloud computer you can open up and watch. It connects to more than 4,000 apps, runs multiple projects in parallel, does read-only “proactive research” while it is idle, and you can message it or call it from web, desktop, mobile, Slack, or Teams. The safety design is actually thoughtful: saved passwords are kept away from the model, password changes always need your approval, you can set your own allow, block, and approval rules, and a monitor can pause the agent when something looks wrong.
This is exactly the agentic future I wrote about in The Death of the Browser Tab. It is the browser tab being demoted in real time.
And OpenAI’s release notes say Pro access “excludes the European Economic Area, Switzerland, and the UK at launch.”
Here is the strange part, and the part I think explains everything.
OpenAI did not say why. No blog post. No regulator to blame. No timeline. Just the exclusion.
And the exclusion is not even total. If you are a business on ChatGPT Business Premium, dots are available “across all supported ChatGPT regions,” Europe and the UK included. So a solo Pro subscriber in London cannot have a dot. A company in London can. Same model. Same agent. Same city.
That detail tells you this is not about whether the technology is allowed to exist in Europe. It is about who carries the risk when an autonomous agent acts on behalf of a private person.
Look at what a dot does through a European regulatory lens. It is an always-on system processing a person’s email, files, calendar, and accounts, building context about their life, and taking actions. Under GDPR, every piece of that needs a legal basis, and profiling and inference about a person are exactly the kind of processing regulators scrutinize. The EU AI Act’s Article 50 transparency obligations kicked in on August 2 this year, with fines up to €15 million or 3% of global revenue. ChatGPT is also reportedly facing obligations under the Digital Services Act. A business customer signs a contract, appoints a data controller, and has a workspace admin who flips the switch. A consumer clicks “I agree.” In the business case, the liability has a home. In the consumer case, it lands squarely on OpenAI.
That is my inference, not OpenAI’s statement. But it is the only reading that explains why the same product is fine for a London company and not for a London person.
The UK case is even more interesting. The UK left the EU partly to escape exactly this kind of regulatory drag, and it still ends up on the wrong side of the rope. UK GDPR is still GDPR in all the ways that matter to an agent rummaging through your inbox. Brexit did not buy the UK out of the risk calculus. It just gave it its own line on the exclusion list.
And dots are not an isolated case. They are a pattern.
- Apple’s new Siri AI is blocked on EU iPhones and iPads at the iOS 27 launch. Apple blames the Digital Markets Act. The European Commission says “the decision not to launch Siri AI in the EU is Apple’s decision and Apple’s alone.”
- Meta’s new Muse agent launched in the US only.
- Codex computer use, the Chrome extension, and memory initially skipped Europe this summer before rolling out a few weeks later.
- ChatGPT Advanced Voice did the same thing back in 2024.

Notice the shape of that. Every major AI company now launches in the US first and treats Europe as a later, separate, lawyered release. Sometimes it is a few weeks. Sometimes it is open-ended. And each side blames the other. The companies blame regulation. The regulators say nothing in the law forbids the launch. Both statements can be true at the same time, and that is precisely the problem. The rules are ambiguous enough that no company wants to be the test case, and the regulators have no incentive to say “yes, this is fine” in advance.
I have said it before and I will say it again: living in Europe right now feels like being a second-class digital citizen. Half the AI features I pay for are gimped or missing. We get attached bottle caps and compliance memos. America gets agents.
Do not bother with a VPN, by the way. I tried. OpenAI has gotten much smarter about region detection, and your account region wins.
I understand the instinct to protect people. I do. An always-on agent with access to your accounts is exactly the kind of thing that deserves careful thought. But protection that arrives as a permanent six-month delay is not protection. It is a tax on the people it claims to protect, paid in lost productivity, lost learning, and lost ground to everyone who got in first.
Why the rope exists at all
It is easy to get angry about velvet ropes. I clearly have. But I think it is worth being honest about why they are going up.
The capability has outrun the trust infrastructure.
We now have models that can find and exploit zero-days. Agents that can escape a sandbox. A cancelled frontier model that misreported its own work. Open-weight models from China that, by Anthropic’s own testing, are building working exploits at rates approaching Mythos Preview. Every lab is staring at the same question: how do you ship something this powerful without handing it to the worst person who will ever use it?
Their answer, for now, is tiering. Defenders before attackers. Enterprises before consumers. Contracts before clickwraps. Jurisdictions with predictable liability before jurisdictions without it. People who pay more before people who pay less.
That is not a conspiracy. It is risk management under uncertainty. But it has a real cost: the people who learn to work with the most capable systems first will compound that advantage, the same way early internet adopters did. The rope is not just a delay. It is a head start for the people on the inside.
That is why my own rule for working with AI has not changed even as the models got shockingly good: the AI gets typing speed, not merge authority. Review the diff. Read the tests. Ask why every abstraction exists. The labs are now applying that exact rule to themselves at civilizational scale. Their models get capability. They do not automatically get release authority.
Where we are headed
This is the part I actually came here to write. Here are my predictions, with dates and confidence levels, so you can hold me to them.

1. Defenders-first becomes the law of the land, not just a lab policy (by end of 2027, 85%)
Every frontier release in 2027 will ship to defenders and vetted partners before the public. Within two years, some version of that gets written into US federal guidance or an industry compact, likely with embedded outside evaluators like the ones Anthropic has already adopted. The labs will welcome it because it turns their current voluntary costs into a level playing field.
2. The flat-rate AI subscription dies (by end of 2027, 80%)
The $20 plan survives as a gateway drug. Everything above it becomes metered, tiered, or credit-based. $500 to $2,000 a month “prosumer” plans become normal for people who run agents all day, the same way serious photographers pay for serious gear. The Pro 20x to 10x cut is the first crack. It will not be the last.
3. Dots, or something like them, reach European and UK consumers, with a European-only consent layer (by mid-2027, 75%)
The exclusion will end, but not quietly. Europe will get a distinct onboarding flow with explicit agent-action logging, data-processing disclosures, and probably a cooling-off approval for account-level actions. The EU will claim this as proof the rules work. The US will see it as proof the rules slow things down. Both will be right. The bigger prediction: “launches in the US first, Europe later” becomes the permanent default for every major AI product through at least 2028, and the average lag settles somewhere between three and six months.
4. The first major agent incident outside a lab happens, and creates a new insurance market (by end of 2027, 70%)
A consumer or enterprise agent will do something expensive on its own: a bad wire, a mass email, a deleted production database, a contract it should not have signed. It will be a big enough story to name. The response will not be a ban. It will be agent liability insurance, audit-log requirements, and spending limits built into every agent product, much like fraud protection became a built-in feature of credit cards.
5. The binding constraint on AI becomes electricity, publicly and politically (by 2028, 80%)
Chips will keep getting better and cheaper. The fights will move to power plants, transmission lines, interconnection queues, and local permitting. AI companies will increasingly behave like utilities: owning generation, signing decades-long power deals, and lobbying on energy policy as hard as they lobby on AI policy. Countries with cheap, abundant, buildable power will quietly become the new AI superpowers.
6. Open-weight models make model-level gating obsolete for cyber (by end of 2028, 70%)
Once open-weight models match today’s Mythos-class cyber capability, and they are already getting close, keeping the best model behind a rope stops protecting anyone. Policy will shift from controlling who can access a model to hardening everything those models can attack. The winners will be the defenders who had early access and used the head start to patch.
7. The entry-level job gets redesigned, not deleted (through 2028, 75%)
The early pain is already showing up as less hiring of young people, not mass firing of experienced ones. The companies that figure it out will turn junior roles into supervised agent-operator roles: one person directing, reviewing, and approving the work of many agents. The skill that matters most will be the one I keep coming back to: taste, judgment, and the willingness to stay awake at the wheel.
8. Your primary interface to software becomes a persistent agent (by 2030, 65%)
Not a chatbot. An agent that knows your context, holds your permissions, works in the background, and checks in when it needs approval. Apps become things agents talk to. Websites grow a second face for machines. The browser tab will not die, but it will become a place you visit to check the agent’s work. Dots are the first mass-market version of this. They will look primitive in four years.
Where I could be wrong
Predictions without a failure mode are just vibes, so here are mine.
If a lab breaks ranks and ships a Mythos-class model openly, the whole defenders-first system could collapse into a free-for-all faster than I expect. If the AI capex wave hits real financing stress, compute could suddenly become abundant and the quota wars could end overnight. And if Europe decides to compete instead of protect, with fast-track agent approvals and clear safe harbors, the geography rope could come down a lot sooner than mid-2027.
I would genuinely love to be wrong about that last one.
The verdict
The last era of AI was about what the machines could do.
This era is about who gets to use them, when, and on what terms.
That is not a less exciting story. It is a more important one. The models are now good enough that access is leverage, and leverage compounds. The people and companies on the inside of the rope are going to learn faster, build faster, and pull ahead faster than at any point in the history of computing.
So my advice is simple. Get as close to the rope as you can. Use the best models you have access to, every day, on real work. Learn to direct agents, not just chat with them. Keep your judgment sharp, because review is the job now. And if you are in Europe like me, make noise. Politely, persistently, and on the record.
The future is here.
It is just checking IDs at the door.

